agentCLAWHUBUnverified

vmware-privateai

Use this skill whenever the user needs the GPU / AI-infrastructure layer of VMware Private AI Foundation with NVIDIA (PAIF-N) on vSphere 9.x / VCF 9.1: inventory GPU hosts and physical GPU devices, see which VMs consume a vGPU and the profile each holds, read real-time GPU utilization, list the vGPU and DirectPath profile catalog, assign a VM's vGPU profile, and list Private AI Service (PAIS) served models and knowledge bases. Always use this skill for "list GPU hosts", "which VMs are using a vGPU", "GPU utilization", "assign a vGPU profile", "list vGPU profiles", "list served models" when the context is explicitly VMware / vSphere / VCF Private AI / NVIDIA vGPU. Do NOT use for the backing VM's power/snapshot/clone/migrate (use vmware-aiops), read-only vSphere inventory/alarms/host health (use vmware-monitor), or GPU-enabled Tanzu Kubernetes (use vmware-vks). This skill is the GPU lens; vmware-aiops owns the VM lifecycle behind it.

OpenClaw

Rank

62

Safety

84

Downloads

1.1k

Updated

Oct 11, 2026

Version

1.4.0

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 10/11/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 11, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 11, 2026
Adoption signal
1.1K downloadsadoption · observed Oct 11, 2026
Latest release
1.4.0release · observed Sep 20, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:vmware-privateai
  1. Install using `clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:vmware-privateai` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/zw008/vmware-privateai before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-privateai/snapshot"

Documentation

CLAWHUB

146,595 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: vmware-privateai
description: >
  Use this skill whenever the user needs the GPU / AI-infrastructure layer of VMware Private AI
  Foundation with NVIDIA (PAIF-N) on vSphere 9.x / VCF 9.1: inventory GPU hosts and physical GPU
  devices, see which VMs consume a vGPU and the profile each holds, read real-time GPU utilization,
  list the vGPU and DirectPath profile catalog, assign a VM's vGPU profile, and list Private AI
  Service (PAIS) served models and knowledge bases. Always use this skill for "list GPU hosts",
  "which VMs are using a vGPU", "GPU utilization", "assign a vGPU profile", "list vGPU profiles",
  "list served models" when the context is explicitly VMware / vSphere / VCF Private AI / NVIDIA
  vGPU. Do NOT use for the backing VM's power/snapshot/clone/migrate (use vmware-aiops), read-only
  vSphere inventory/alarms/host health (use vmware-monitor), or GPU-enabled Tanzu Kubernetes
  (use vmware-vks). This skill is the GPU lens; vmware-aiops owns the VM lifecycle behind it.
installer:
  kind: uv
  package: vmware-privateai
allowed-tools:
  - Bash
metadata: {"openclaw":{"requires":{"anyBins":["vmware-privateai","uvx"]},"optional":{"env":["VMWARE_PRIVATEAI_CONFIG"]}}}
---

# VMware Private AI (Foundation with NVIDIA) — GPU & Model-Serving Ops

> **Disclaimer**: Community-maintained open-source project, **not affiliated with, endorsed by, or
> sponsored by VMware, Inc., Broadcom Inc., or NVIDIA Corporation.** "VMware", "vSphere", and "VCF"
> are trademarks of Broadcom; "NVIDIA" and "vGPU" are trademarks of NVIDIA. Source is publicly
> auditable under the MIT license.

The GPU / AI-infrastructure lens for the VMware skill family — GPU host & device inventory, vGPU
consumers, real-time GPU utilization, the vGPU / DirectPath profile catalog, vGPU assignment, and
**Private AI Service (PAIS)** served models and knowledge bases — over the **vSphere 9.x / VCF 9.1**
Web Services API (pyVmomi) plus the PAIS REST API.

> **Companion skills**: [vmware-aiops](https://github.com/vmware-skills/VMware-AIops) (the vCenter VMs
> behind AI workloads — power/snapshot/clone), [vmware-vks](https://github.com/vmware-skills/VMware-VKS)
> (GPU-enabled Tanzu Kubernetes), [vmware-monitor](https://github.com/vmware-skills/VMware-Monitor)
> (read-only vSphere health).

> **Status: v1.0.1 — still beta in substance.** Skill #15 of the family. The jump from 0.2.x to
> 1.0.1 is a distribution fix, not a maturity claim: the withdrawn first release used 1.0.0, and
> ClawHub resolves `latest` by version order, so every 0.x release was invisible there. The beta
> caveats below all still stand. Every API path is
> verified against official Broadcom/NVIDIA sources before use (`tests/eval/spec/privateai_endpoints.py`)
> — no endpoints written from memory. GET-response *field names* and the exact PAIS paths are
> defensive and pending validation against live 9.x hardware (see Troubleshooting). Governed by the
> family harness (audit + policy + teaching errors); read-vs-

_meta.json

{
  "ownerId": "kn7b067awq2s97bn3d7p5qfhw5827pxc",
  "slug": "vmware-privateai",
  "version": "1.4.0",
  "publishedAt": 1789915986383
}

references/capabilities.md

# vmware-privateai — Capabilities

17 MCP tools (16 read / 1 write) over the vSphere 9.x / VCF 9.1 Web Services API (pyVmomi) plus the
Private AI Service (PAIS) REST API, with two tools that need no connection at all (sizing / bundle).
Every vSphere tool accepts an optional `target`; PAIS tools use the `pais:` config section instead.
Typical response tokens are estimates for a small estate; every `*_list` tool paginates at `limit=50`
and returns the `{items, returned, limit, offset, total, truncated, hint}` envelope.

## GPU inventory (4 read)
| Tool | R/W | Returns | ~tokens |
|------|:---:|---------|:------:|
| `gpu_host_list` | R | host, gpu_count, vendors[], vgpu_vms (filter name/vendor) | 60–400 |
| `gpu_host_get` | R | one host's GPUs: device, type, vendor, memory_mb, pci_id, vm_count | 80–400 |
| `gpu_device_list` | R | flattened physical GPUs: host, device, type, vendor, pci_id, memory_mb, vm_count (filter host/vendor) | 80–600 |
| `gpu_consumer_list` | R | vm, profile — the "who holds a vGPU" view (filter profile/vm) | 60–500 |

## GPU utilization (1 read)
| Tool | R/W | Returns | ~tokens |
|------|:---:|---------|:------:|
| `gpu_utilization` | R | vm, profile, gpu_pct, mem_pct, mem_used_kb, temp_c, metrics_available, idle; busiest first, `top` keeps N | 80–500 |

Real-time 20s samples via the vSphere PerformanceManager `gpu.*` counters (require the NVIDIA host GPU
driver). A negative sample is vSphere's "no data" sentinel and is dropped; a VM with no samples reports
`metrics_available:false`. **Beta caveat**: the `gpu.*` counters may report at host level on some
builds — verify the entity type on real hardware. Deep per-SM / per-process / MIG-slice telemetry is
**not** in vSphere (needs NVIDIA DCGM) and no endpoint is invented for it.

## GPU readiness (1 read)
| Tool | R/W | Returns | ~tokens |
|------|:---:|---------|:------:|
| `gpu_host_readiness` | R | host, vgpu_ready, gpu_count, vendors[], total_gpu_memory_mb, default_graphics_type, vgpu_profiles_offered, active_vgpu_vms, blocking_reasons[], driver_note (filter/scope host) | 100–600 |

Combines `config.graphicsInfo` + `config.graphicsConfig` + the per-host `QueryConfigTarget` profile
catalog into a `vgpu_ready` verdict (GPU present + `sharedDirect` mode + ≥1 profile offered). Only
GPU hosts are returned; a per-host query failure lands in `unreachable_hosts`. The NVIDIA driver /
MFT VIB version and MIG geometry are **not** in the vSphere API — every item carries a `driver_note`
routing to `nvidia-smi` / `esxcli` (spec NO_API; no endpoint invented).

## Profile catalog (2 read)
| Tool | R/W | Returns | ~tokens |
|------|:---:|---------|:------:|
| `vgpu_profile_list` | R | profile, name, framebuffer_gib, profile_class, sharing, vendor_id, hosts[], host_count, unreachable_hosts[] (filter/scope host, filter model) | 80–600 |
| `directpath_profile_list` | R | id, name, vendor, description — vCenter-level DirectPath profiles, **vSphere 9.0+** (filter name/vendor) | 60–400 |

`vgpu_pro

references/cli-reference.md

# vmware-privateai — CLI Reference

Full command list for the `vmware-privateai` Typer CLI. Every read command prints a teaching error and
exits 1 (never a traceback) on a config / not-found / connection problem. Every command accepts
`--target <name>` (a vCenter/ESXi target from `config.yaml`; omit for the default) and `--config <path>`
(override the `~/.vmware-privateai/config.yaml` location). Reads paginate at 50 rows; use the filter
options rather than paging the whole estate.

## Top level

```bash
vmware-privateai version          # print the installed version
vmware-privateai mcp              # run the stdio MCP server (used by MCP clients)
vmware-privateai --help           # list command groups: gpu, vgpu, pais
```

> The `mcp` subcommand is the recommended MCP entry point — it is an installed console script, so it
> never re-resolves from PyPI the way `uvx` does (踩坑 #25: `uvx` is fragile behind an enterprise TLS
> proxy). MCP clients should launch `vmware-privateai mcp`.

## `gpu` — GPU inventory, utilization, and vGPU assignment

```bash
vmware-privateai gpu host-list [--name N] [--vendor V] [--target T] [--config PATH]
```
List ESXi hosts that have at least one GPU. Columns: host, gpu_count, vendors, vgpu_vms. `--name`
substring-matches the host name; `--vendor` substring-matches the GPU vendor (e.g. `NVIDIA`).

```bash
vmware-privateai gpu host-get <host_name> [--target T] [--config PATH]
```
Full per-GPU detail for one host: device, graphics type, vendor, memory (MB), pci id, vm_count. A wrong
host name prints a teaching error listing the hosts that do have GPUs.

```bash
vmware-privateai gpu device-list [--host H] [--vendor V] [--target T] [--config PATH]
```
Flattened list of physical GPU devices across hosts. Columns: host, device, type, vendor, memory (MB),
vm_count. `vm_count 0` marks an idle GPU.

```bash
vmware-privateai gpu consumer-list [--profile P] [--vm V] [--target T] [--config PATH]
```
List VMs consuming a vGPU and the profile each holds (e.g. `grid_a100-4c`). `--profile` / `--vm`
substring-filter.

```bash
vmware-privateai gpu utilization [--vm V] [--top N] [--target T] [--config PATH]
```
Real-time (20s sample) GPU utilization per vGPU VM, busiest first: gpu %, mem %, temp (C). `--top N`
keeps only the N busiest. A VM with no host-driver samples prints `metrics unavailable` (not an error).

```bash
vmware-privateai gpu vgpu-assign <vm_name> <profile> [--dry-run] [--target T] [--config PATH]
```
**WRITE.** Set a VM's vGPU profile. Always prints the preview (current → target profile, power state,
requires_power_off) first. `--dry-run` stops there. Otherwise requires **double confirmation**, then
applies via ReconfigVM and audits the result. The VM must be powered **off** — a running or suspended VM
is refused with a teaching error routing you to `vmware-aiops vm_power_off`, and so is a name shared by
several VMs or a VM whose power state or devices could not be read. This command never powers the VM off
itself.

```bas

references/setup-guide.md

# vmware-privateai — Setup Guide

> **Disclaimer**: Community-maintained open-source project, **not affiliated with, endorsed by, or
> sponsored by VMware, Inc., Broadcom Inc., or NVIDIA Corporation.** "VMware", "vSphere", and "VCF" are
> trademarks of Broadcom; "NVIDIA" and "vGPU" are trademarks of NVIDIA. Source is publicly auditable
> under the MIT license.

Install, credential, and MCP-client configuration for vmware-privateai, plus the Security section.

## 1. Install

```bash
uv tool install vmware-privateai==1.4.0       # isolated tool env; puts vmware-privateai on PATH
vmware-privateai version
```

Requires Python 3.11+ (the MCP server is reflected by FastMCP/Pydantic; older interpreters can raise on
PEP 604 unions — 踩坑 #33). Runtime deps: pyvmomi, httpx, typer, rich, pyyaml, python-dotenv, mcp, and
`vmware-policy` (the family audit/policy harness, installed automatically).

## 2. Configure targets

Create `~/.vmware-privateai/config.yaml`:

```yaml
targets:
  - name: vc-prod
    host: vcenter-prod.example.com
    username: [email protected]   # optional; env var overrides this
    type: vcenter                            # or esxi
    port: 443
    verify_ssl: true
    environment: production                  # optional label for policy scoping

# Optional — only needed for the pais model-list / kb-list tools:
pais:
  endpoint: https://pais.example.com         # base URL; the /api/v1 prefix is added by the client
  verify_ssl: true
```

The first target is the default (used when `--target` / the `target` MCP arg is omitted).

## 3. Credentials — never in config files

Passwords and the PAIS bearer token live only in `~/.vmware-privateai/.env`:

```bash
mkdir -p ~/.vmware-privateai
cat >> ~/.vmware-privateai/.env <<'EOF'
VMWARE_PRIVATEAI_VC_PROD_PASSWORD=your-vcenter-password
VMWARE_PRIVATEAI_PAIS_TOKEN=your-oidc-bearer-token
EOF
chmod 600 ~/.vmware-privateai/.env
```

- **Per-target password**: `VMWARE_PRIVATEAI_<TARGET>_PASSWORD`, where `<TARGET>` is the target `name`
  upper-cased with `-` replaced by `_` (so target `vc-prod` → `VMWARE_PRIVATEAI_VC_PROD_PASSWORD`).
- **Optional username override**: `VMWARE_PRIVATEAI_<TARGET>_USERNAME` wins over `config.yaml` (resolved
  together with the password on every call, so a rotating sidecar never splits the pair).
- **PAIS token**: `VMWARE_PRIVATEAI_PAIS_TOKEN` — a short-lived OIDC/OAuth2 bearer token from your
  Identity Provider (the PAIS API uses `Authorization: Bearer <token>`). It is a secret and is
  obfuscated to `b64:` at rest exactly like a password.
- **Secret manager**: any of these vars can be injected from Vault / CyberArk / AWS Secrets Manager /
  a Kubernetes Secret instead of `.env` — the code reads the environment either way.

On load, plaintext `*_PASSWORD` / `*_TOKEN` values in `.env` are auto-rewritten to grep-safe `b64:`
form (obfuscation, not encryption — it defeats casual grep / shoulder-surfing, not a determined reader).

## 4. MCP client configuration

Prefer
Github ReposUpdated 2d agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/zw008/skills/vmware-privateai",
      "sourceUrl": "https://clawhub.ai/zw008/skills/vmware-privateai",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T11:46:55.190Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-privateai/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-privateai/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-11T11:46:55.190Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.1K downloads",
      "href": "https://clawhub.ai/zw008/vmware-privateai",
      "sourceUrl": "https://clawhub.ai/zw008/vmware-privateai",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T11:46:55.190Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "1.4.0",
      "href": "https://clawhub.ai/zw008/vmware-privateai",
      "sourceUrl": "https://clawhub.ai/zw008/vmware-privateai",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-20T14:53:06.383Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-privateai/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-privateai/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.4.0",
      "description": "MCP instructions now name the configured targets and how to choose one; a config that cannot be read says so instead of falling silent.",
      "href": "https://clawhub.ai/zw008/vmware-privateai",
      "sourceUrl": "https://clawhub.ai/zw008/vmware-privateai",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-20T14:53:06.383Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 11, 2026.

Sponsored

Ads related to vmware-privateai and adjacent AI workflows.